Answered: [Security threat] tags are not sanitized in extra question field

Post date: 2020-07-01 00:44:51
Views: 198

Hey q2apro, I think you are testing the default q_view_extra($q_view); function.

The default function is still safe. But if you pull the content from the databse, it's not safe.

First, look! The script is stored in database.

database

Second, if create a function to pull that content form the datase:

public function q_item_extra($q_item)
{
$postidz = $q_item'raw']'postid'];
$extra = qa_db_read_one_value(qa_db_query_sub(
       'SELECT content FROM ^postmetas WHERE title="qa_q_extra" AND postid=#',
        $postidz
   ), true);
 
 //$extra = $q_item'extra']'content'];
 
        $this->output('My info:'.$extra);   
   
}

Here's the result:

test

I hope you'll get my point.

Please click Here to read the full story.
 
Other Top and Latest Questions:
Pentagon to invest $1 billion in L3Harris rocket motor business, shares surge
Does it really matter who ends up owning Warner Bros.? Media exec Tom Rogers breaks it down
RV buyers are trading up and this stock is set to benefit, Loop Capital says
Bank of America boosts Micron price target, sees upside driven by tight memory supply
Salesforce releases updated Slackbot powered by Anthropic's AI model
Rates have dropped to the lowest point in years — here are the best lenders for refinancing your mortgage
South Korea's ex-president Yoon given 5-year jail term in first ruling over martial law
This Korean retail giant has been under pressure. Deutsche Bank thinks the bad news is baked in
U.S. threats of a Greenland takeover spark talk of trade wars
Here are Needham's top picks for 2026